# Sum aggregation question

**URL:** <https://discuss.elastic.co/t/sum-aggregation-question/180885>\
**Category:** Elasticsearch\
**Created:** [May 13, 2019, 8:40pm UTC](https://discuss.elastic.co/t/sum-aggregation-question/180885 "2019-05-13T20:40:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmerritt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmerritt/32/46107_2.png) [@tmerritt](https://discuss.elastic.co/u/tmerritt)\
**Post date:** [May 13, 2019, 8:40pm UTC](https://discuss.elastic.co/t/sum-aggregation-question/180885/1 "2019-05-13T20:40:52Z")

</div>

I'm trying to use the elastic search integration in pcp to load metrics to ES and visualize them via grafana. It's mostly working except for some of the stats that pcp aggregates as associative arrays.  
Load averages are stored as

```auto
"@instances": [
                {
                  "load": 8,
                  "@id": "1 minute"
                },
                {
                  "load": 8,
                  "@id": "5 minute"
                },
                {
                  "load": 8.1,
                  "@id": "15 minute"
                }
              ],

```

for instance. When I try to visualize that with the query below though, ES sums all of the 1, 5, and 15 minute values together and returns a single identical value for all three metrics. Is there a way to get ES to sum the three values separately?

```auto
{
    "size":0,
    "query":{
        "bool":{
            "filter":[
                {
                    "range":{
                        "@timestamp":{
                            "gte":"1557750800000",
                            "lte":"1557750940001",
                            "format":"epoch_millis"
                        }
                    }
                },
                {
                    "query_string":{
                        "analyze_wildcard":true,
                        "query":"@host-id:cpu1"
                    }
                }
            ]
        }
    },
    "aggs":{
        "3":{
            "terms":{
                "field":"kernel.all.@instances.@id.keyword",
                "size":100,
                "order":{
                    "_term":"desc"
                },
                "min_doc_count":1
            },
            "aggs":{
                "2":{
                    "date_histogram":{
                        "interval":"1m",
                        "field":"@timestamp",
                        "min_doc_count":0,
                        "extended_bounds":{
                            "min":"1557750800000",
                            "max":"1557750940001"
                        },
                        "format":"epoch_millis"
                    },
                    "aggs":{
                        "1":{
                            "sum":{
                                "field":"kernel.all.@instances.load"
                            }
                        }
                    }
                }
            }
        }
    }

```

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [May 17, 2019, 3:37pm UTC](https://discuss.elastic.co/t/sum-aggregation-question/180885/2 "2019-05-17T15:37:21Z")

</div>

So in this case, the issue is the array of objects. In Elasticsearch, arrays of objects are "flattened" into arrays and does not maintain ordering. So the relationship between the load and the ID is lost during the flattening.

This part of the Guide is quite old so some of the syntax might be out-dated, but the explanation of the phenomenon is still valid: [https://www.elastic.co/guide/en/elasticsearch/guide/current/complex-core-fields.html#object-arrays](https://www.elastic.co/guide/en/elasticsearch/guide/current/complex-core-fields.html#object-arrays)

Essentially, you'll need to either use one of the relational fields (nested datatype, or parent/child), or just use different fields like `5_min_load`, `15_min_load`, etc

---

<div class="post-metadata">

**Author:** ![tmerritt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmerritt/32/46107_2.png) [@tmerritt](https://discuss.elastic.co/u/tmerritt)\
**Post date:** [May 17, 2019, 4:30pm UTC](https://discuss.elastic.co/t/sum-aggregation-question/180885/3 "2019-05-17T16:30:13Z")

</div>

Thanks for the confirmation. I ended up writing my own metric agent for pcp that stores them in separate flat values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2019, 4:30pm UTC](https://discuss.elastic.co/t/sum-aggregation-question/180885/4 "2019-06-14T16:30:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
